CVE-2026-4630
בינונית 6.8
תיאור (מקור, אנגלית)
A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same realm, the client could bypass authorization checks. This allows the client to perform unauthorized GET, PUT, and DELETE operations on resources, leading to information disclosure and potential unauthorized modification or deletion of data.
מדדים
- CVSS 3.1
-
6.8 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-4/8/2026
- CWE
- CWE-639
מוצרים מושפעים
redhat: build of keycloak
קישורים
- https://access.redhat.com/errata/RHSA-2026:19596 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:19597 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-4630 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2450245 Vendor Advisory